Skip to main content

Vendor/product archive

wso2 / identity_server CVEs

Beta · best-effort

70 CVEs tagged to wso2 / identity_server6 Critical, 13 High, 48 Medium, 3 Low, 0 Unrated.

CVE-2025-13475

Published Jul 4, 2026

In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific Saa…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-9973

Published May 11, 2026

Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication logic to be triggered on unint…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-10470

Published May 11, 2026

The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-10908

Published May 11, 2026

Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass Key methods. This bypasses th…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-10503

Published Apr 29, 2026

The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injecti…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-12624

Published Apr 16, 2026

Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation allows previously issued, valid t…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-6024

Published Apr 16, 2026

The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can leverage this by injecting mali…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1524

Published Feb 24, 2026

When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk that a local user store user's information may be replaced…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-12107

Published Feb 19, 2026

Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side tem…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-10853

Published Nov 5, 2025

A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific paramet…

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-10907

Published Nov 5, 2025

An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious acto…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-5350

Published Oct 24, 2025

SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accept…

CVSS 5.9 · Medium

CVE-2025-10611

Published Oct 16, 2025

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 70 CVEsPage 1 of 3